[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-127857-en":3,"doc-seo-127857-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},127857,2336474466712,"Maeve","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",6,"Technology","Deployment Guidelines for Industry - Machine Learning-based Intrusion Detection Systems","Deployment Guidelines for Industry focuses on using machine learning for intrusion detection systems in industrial environments, with special attention to cyber-physical and industrial control systems. The document covers attacker context and recent incidents, explains intrusion detection types and anomaly-based approaches, and details the end-to-end machine learning pipeline. It guides dataset acquisition and preparation, anomaly and model selection, training and performance assessment, deployment and ongoing maintenance, and highlights practical challenges and limitations.","SUPPLY CHAINS AND CONTROL SYSTEMS  \nDeployment Guidelines for Industry: Machine Learning-based Intrusion Detection Systems  \nMachine Learning-based Intrusion Detection Systems  \nDeployment Guidelines for Industry  \nAuthors  \nShreevanth Gopalakrishnan Dr Nilufer Tuptuk  \nProf. Stephen Hailes  \nUniversity College London  \nTHE PETRAS NATIONAL CENTRE OF EXCELLENCE FOR IoT SYSTEMS CYBERSECURITY  \nSUPPLY CHAINS AND CONTROL SYSTEMS  \nDeployment Guidelines for Industry: Machine Learning-based  \nIntrusion Detection Systems  \nContents  \nAbout PETRAS 3  \nAbbreviations 4  \n1. Executive Summary 6  \n2. Key Recommendations 7  \n3. Background 9  \n3.1 Attacks on ICS 9  \n3.2 Recent Attacks 15  \n4. Intrusion Detection Systems 18  \n4.1 What Are They 18  \n4.2 Types of Intrusion Detection Systems 20  \n4.3 Comercially Available IDS Solutions 22  \n4.4 Anomaly-Based Intrusion Detection Systems 24  \n5. Application of Machine Learning 25  \n5.1 Acquiring and Preparing Machine Learning Datasets 25  \n5.2 Types of Anomalies 31  \n5.3 Types of Detection Models Available 33  \n5.4 Selecting a Detection Model 39  \n5.5 Training the Detection Model and Assessing Performance 41  \n5.6 Deploying and Maintaining the Model 46  \n5.7 Challenges/Limitations of ML-based Anomaly Detection 50  \n6. Closing Remarks 52  \n7. References 53  \nAPX Appendices 61  \nA. Project Details 61  \nB. Purdue Reference Architecture 61  \nC. Differences between IT and OT Systems 63  \nD. Security Issues and Challenges of ICS 64  \nTHE PETRAS NATIONAL CENTRE OF EXCELLENCE FOR IoT SYSTEMS CYBERSECURITY March 2023 | Page 2  \nSUPPLY CHAINS AND CONTROL SYSTEMS  \nDeployment Guidelines for Industry: Machine Learning-based Intrusion Detection Systems  \nAbout PETRAS  \nThe PETRAS National Centre of Excellence for IoT Systems Cybersecurity exists to ensure that technological advances in the Internet of Things (IoT) are developed and applied in consumer and business contexts, safely and securely. This is done by considering social and technical issues relating to the cybersecurity of IoT devices, systems and networks.  \nTo achieve our objectives, PETRAS works in collaboration with academia, industry and government partners to ensure our research can be directly applied to benefit society, business and the economy.  \nThe Centre is a consortium of 23 research institutions and the world’s largest socio-technical research centre focused on the future implementation of the Internet of Things. The research institutions are: UCL, Imperial College London, University of Bristol, Cardiff University, Coventry University, University of Edinburgh, University of Glasgow, Lancaster University, Newcastle University, Northumbria University, University of Nottingham, University of Oxford, University of Southampton, University of Surrey, Tate, the University of Warwick and Keele University.  \nAs part of UKRI’s Security of Digital Technologies at the Periphery (SDTaP) programme, PETRAS runs open, national level funding calls which enable us to undertake cutting edge basic and applied research. We also support the early adoption of new technologies through close work with other members of the  \nSDTaP programme, such as InnovateUK, supporting demonstrations of new technology and commercialisation processes.  \nTHE PETRAS NATIONAL CENTRE OF EXCELLENCE FOR IoT SYSTEMS CYBERSECURITY March 2023 | Page 3  \nSUPPLY CHAINS AND CONTROL SYSTEMS  \nDeployment Guidelines for Industry: Machine Learning-based  \nIntrusion Detection Systems  \nAbbreviations  \n| AI\u003Cbr>API\u003Cbr>AUC\u003Cbr>CGI\u003Cbr>COPOD\u003Cbr>CRM\u003Cbr>DCS\u003Cbr>DL\u003Cbr>DNP3\u003Cbr>DoS\u003Cbr>DWTMLEAD\u003Cbr>EMS\u003Cbr>EUC\u003Cbr>Fast-MCD\u003Cbr>FFT\u003Cbr>FP\u003Cbr>FTP\u003Cbr>HBOS\u003Cbr>HIF\u003Cbr>HMI\u003Cbr>I/O\u003Cbr>ICS\u003Cbr>IoT\u003Cbr>IT\u003Cbr>K-S | Artificial Intelligence\u003Cbr>Application Programming Interfacing\u003Cbr>Area Under Curve Common Gateway Interface\u003Cbr>Copula-Based Outlier Detection\u003Cbr>Customer Relationship Management\u003Cbr>Distributed Control System Deep Learning\u003Cbr>Distributed Network Protocol 3\u003Cbr>Denial of Service\u003Cbr>Discrete Wavelet Transformsand Maxi","cbCaiiQNRrCWrbuk","https://ap.wps.com/l/cbCaiiQNRrCWrbuk","pdf",1270062,2,1,66,"English","en",105,"# Executive Summary\n# Key Recommendations\n# Background\n## Attacks on ICS\n## Recent Attacks\n# Intrusion Detection Systems\n## What Are They\n## Types of Intrusion Detection Systems\n## Comercially Available IDS Solutions\n## Anomaly-Based Intrusion Detection Systems\n# Application of Machine Learning\n## Acquiring and Preparing Machine Learning Datasets\n## Types of Anomalies\n## Types of Detection Models Available\n## Selecting a Detection Model\n## Training the Detection Model and Assessing Performance\n## Deploying and Maintaining the Model\n## Challenges/Limitations of ML-based Anomaly Detection\n# Closing Remarks\n# References","[{\"question\":\"What is the scope of the deployment guidelines for industry?\",\"answer\":\"The guidelines focus on deploying machine learning-based intrusion detection systems in industrial environments, considering relevant cybersecurity context for industrial control systems and related infrastructure.\"},{\"question\":\"How does the document support the machine learning workflow for intrusion detection?\",\"answer\":\"It covers acquiring and preparing datasets, identifying types of anomalies, selecting detection models, training and assessing performance, and then deploying and maintaining the trained model.\"},{\"question\":\"What challenges and limitations are highlighted for ML-based anomaly detection?\",\"answer\":\"The document includes a dedicated section on challenges and limitations, addressing practical risks and constraints that affect real-world anomaly detection performance.\"}]","Deployment Guidelines for Industry - Machine Learning-based Intrusion Detection Systems | PDF",1785942383,166,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"deployment-guidelines-for-industry-machine-learning-based-intrusion-detection-systems","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/deployment-guidelines-for-industry-machine-learning-based-intrusion-detection-systems/127857/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-27","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the scope of the deployment guidelines for industry?","Question",{"text":76,"@type":77},"The guidelines focus on deploying machine learning-based intrusion detection systems in industrial environments, considering relevant cybersecurity context for industrial control systems and related infrastructure.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the document support the machine learning workflow for intrusion detection?",{"text":81,"@type":77},"It covers acquiring and preparing datasets, identifying types of anomalies, selecting detection models, training and assessing performance, and then deploying and maintaining the trained model.",{"name":83,"@type":74,"acceptedAnswer":84},"What challenges and limitations are highlighted for ML-based anomaly detection?",{"text":85,"@type":77},"The document includes a dedicated section on challenges and limitations, addressing practical risks and constraints that affect real-world anomaly detection performance.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,114,119,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":112,"slug":113},50,"technology",{"id":115,"doc_module":4,"doc_module_name":47,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":120,"doc_module":4,"doc_module_name":47,"category_name":121,"show_sort_weight":122,"slug":123},8,"Research & Report",30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]